63 comments

  • simonw a day ago ago

    Crypto's greatest weakness has always been security. Even if the algorithms themselves hold, humans need to keep their keys safe. We have decades of experience now showing that humans can't do that.

    I wouldn't be worrying about the algorithms so much as I'd worry about all of the end-users who are going to get their keys stolen and their wallets drained thanks to the deluge of new vulnerabilities in operating systems, browsers, wallets, personal agents and other software.

  • int32_64 a day ago ago

    The guy that made the 'bunker mode' tweet is an Ethereum guy, the chain that they reorganized when the wrong people lost money in the DAO hack.

    What good are strong cryptography primitives for cryptocurrency if your "CEO" can successfully make calls to reorganize the chain?

    • kinakomochidayo 18 hours ago ago

      The chain wasn’t “reorganized”. It was an unusual state change in a smart contract, agreed by node operators.

      Let’s also not forget that Satoshi actually rolled back the chain in 2010 after a hacker printed 184 billion BTC.

    • pants2 a day ago ago

      That was over 10 years ago now, when the chain was less than a year old. Things have changed. Can we drop it already?

      • tzs 21 hours ago ago

        I haven't followed this subject. What's changed?

        • pants2 18 hours ago ago

          Basically everything. DeFi wasn't even really a thing back then - Ethereum had zero TVL when the rollback happened. Smart contracts were a brand new concept. Competing SC chains like Solana weren't even in the idea stage yet. It also had only one client. Now there is $50B+ in TVL and nine clients and a rollback is just not going to happen.

          It's ancient history. It's like still criticizing Apple for how they handled Copland OS.

      • kayamon a day ago ago

        We won't drop it. Ethereum was built on insecure management from day one. Satoshi proved that honest mining nodes follow the longest proof-of-work chain. Ethereum chose to start their own management and now continue to suffer the consequences.

        • kinakomochidayo 18 hours ago ago

          Satoshi literally rolled back the chain in 2010 after the value overflow bug. Hilarious.

          Ethereum only did a surgical state change on a smart contract. It wasn’t a rollback like Satoshi.

        • pants2 18 hours ago ago

          What "consequences" are you referring to? Anything that has happened in the last 10 years?

    • whattheheckheck a day ago ago

      When it makes sense. Eth classic was a psy op from cardano guy.

  • gumby a day ago ago

    I'm a bit concerned about starting a flame war, but I barely follow any cryptocurrency news at all. So I am curious: would there actually be any negative macro consequence if this were to happen?

    I know, at the micro level some people would lose their money, but does bitcoin (or any cryptocurrency) have any practical, legitimate use with visible impact on the global economy (or even the national eonomy of any country with major footprint)? And I'd be sad for some of those people. but would it have any impact that I would notice? My money is in broad, boring index funds.

    • DaveFr a day ago ago

      Depends on your definition of "legitimate", but Iran uses cryptocurrency to tax oil tankers going through the Strait of Hormuz. There is certainly some practical impact. https://finance.yahoo.com/markets/crypto/articles/iran-turns...

      • gumby a day ago ago

        Interesting use case. Not formally legitimate but even the US would prefer it not be stopped as even small exports exert a large impact on the price of oil.

        But a good example of a macro impact on the global economy.

    • gucci-on-fleek a day ago ago

      > but does bitcoin (or any cryptocurrency) have any practical, legitimate use with visible impact on the global economy (or even the national eonomy of any country with major footprint)?

      I've read anecdotes on HN that it's used quite a bit for remittances to some countries with unstable currencies, but my understanding is that nearly all of these users are immediately converting it to the local currency, so the only money at risk would be that which is in active transit. It would definitely be unfortunate to lose any money being transferred, but remittance recipients don't tend to have any savings at all, so I don't think that it would have any broader economic effects (in the context of this specific example).

      It could also potentially mess with electricity prices in some areas, since Bitcoin mining uses quite a bit of power, but I suspect that some AI datacenter would step in and buy up all the excess power, so this probably wouldn't be much of an issue either.

      (And I don't know enough to comment about how this could affect other sectors of the economy)

      • dumberquestions a day ago ago

        > I've read anecdotes on HN that it's used quite a bit for remittances to some countries with unstable currencies

        I can confirm that this aspect is absolutely massive and often underestimated by those living in the West.

        It's happening all over Africa, Middle East and LATAM, since stablecoin transactions are cheaper and require no access to financial infrastructure that could be locally unavailable, but as you mentioned it's only used as an intermediate link before converting to local currency.

        • gumby 18 hours ago ago

          Interesting!

          I just looked up the world bank’s estimates which say remittances are around $850B (including direct co-party islamic cash transfers, illegal in many countries). The amount using crypto is about $26B, so about 3%, hardly material at a macro scale (might be a big deal for a small country) so losing this would not be noticeable to the global economy.

          • dumberquestions 2 hours ago ago

            You could delete a small country from existence and it wouldn't affect the global economy much, not the best measure of impact imo.

    • logicalmind a day ago ago

      There are two layers of value on chains that are not bitcoin. There is the native currency and then various forms of tokens that can be transacted. Tokens are things like NFT's or Stablecoins. In order to trade tokens you need to pay gas in the native currency of the chain. For example, ETH on the Ethereum network.

      Large financial institutions are already doing work using stablecoins. In order to turn stablecoins back into fiat, you have to take them back to the issuer for exchange. Countries with unstable currencies can hold USD by purchasing stablecoins. And financial institutions can do settlement between each other using stablecoins.

      • gumby 17 hours ago ago

        Federal reserve (Kansas) says in ‘25 these transactions were about $390B (there are qild estimates of $35T but these seem to be typos or deliberate misreadings of a prediction for 2035 from a crypto enthusiast). At forex scale or the scale of global GDP, 400B is invisible.

        It could grow, of course, though the use case appears to be weak and unstable countries, which are by definition distant participants of global exchange, and unlikely to have any visible effect on the overall macro economy.

        • logicalmind 5 hours ago ago

          I don't disagree, but there is a lot of hesitancy at financial institutions right now because the regulations are all over the place. I think what we are seeing now are MVP use cases that people are willing to try before regulations are finalized. There are some very large (macro-level) use cases possible, but the regulations have to allow for that.

    • mceleri a day ago ago

      Well... Elliptic curve cryptography is also used in many other systems and connections, so yes, we would all notice if a mathematical trick broke it.

      • gumby 17 hours ago ago

        Very much so! Though I was looking at the use case of the OP.

  • notnullorvoid a day ago ago

    My gut is telling me pushing security model to hashes seems like a far far worse bet if you are worried about advances in maths.

    • MattPalmer1086 a day ago ago

      The point is they have less algebraic structure than things like elliptic curves. If you want "math resistant" properties, this is a good thing.

    • palmotea a day ago ago

      > My gut is telling me pushing security model to hashes seems like a far far worse bet if you are worried about advances in maths.

      Aren't hashes far less reliant on math tricks?

      My understanding is the problem with public-key crypto is it extremely reliant on a single math trick (e.g. the factoring problem), so if it turns out that trick was weaker than was assumed, the whole thing crumbles.

      • tptacek a day ago ago

        Yes. Symmetric cryptography doesn't generally rely on the existence of "trap doors", so there's no direct relationship in any sense between the inputs and the outputs. Huge portions of the cryptographic attack surface are foreclosed in these constructions.

    • jMyles a day ago ago

      That's the opposite of what my gut is telling me.

      Hashes are so simple. There's no place for these crazy math attacks, which rely on rethinking long-standing and otherwise reasonable assumptions, to hide.

      Surely we can all agree that there's no way to reverse a modulus.

      • notnullorvoid 21 hours ago ago

        The risk isn't about reversing the hash, it's about finding a hash collision. If the hash is the only reference to your public key on chain, one does not need to reverse the hash, they just need produce a key pair who's public hash collides.

        Currently that's a large brute force problem. But my gut is telling me is that finding a forward pass method of restraining private key generation such that we know what kind of public key hash to expect at the end, should be easier than cracking elliptic curves.

        I guess depending on your outlook some might view that as "reversing" a hash, but it's not like you are getting the original input which is a impossible problem (unless there is a bunch of info you already know about the input).

      • tptacek a day ago ago

        I think I agree with you in spirit but I don't think "there's no way to reverse a modulus" is the right way to say this. Like that's in a sense what Coppersmith does? (Several attacks on RSA can be thought of as in some way "reversing a modulus").

        • jMyles a day ago ago

          > I think I agree with you in spirit

          holy heck, the planets have aligned, HN

          ;-)

          • tptacek a day ago ago

            We both work in security, right? That shouldn't surprise you so much.

            • jMyles a day ago ago

              Actually man, I've transitioned pretty much full-time to playing bluegrass. Given that my life has been spend watching and helping the internet grow, most of my songs are about what it has felt like to live amidst that: https://justinholmes.bandcamp.com/

              I still hack every day (current project: pickipedia.xyz), but I'm not doing security anymore except for my own projects.

              And yes, I was more making light of what seem to me to largely be political disagreements; of course I respect your work at the same time.

              It seems clearer and clearer to me that nationa-states cannot possibly withstand the evolution of the internet in any dignified way, and I pray for peaceful, simple deprecation of them. It seems to me to be the sensible stance, both in terms of security and in terms of joy.

              My repeated sense - right honed or wrongly - is that you defend these structures (nation-states generally, and intelligence operations / state secret brokers in particular) in ways that I find hard to reconcile, even upon extended reflection.

              • tptacek 8 hours ago ago

                Uh, ok, I was just saying my security takes are pretty normie and easy to agree with.

      • dist-epoch a day ago ago

        Isn't it more secure mostly because of the mixing than the modulus.

  • search_facility a day ago ago

    May be Ethereum should fund 10000 agents to pursue new crypto math with provable strongness/hardness

    • Lerc a day ago ago

      I think much of the the doomer propaganda is paid for by by the half billion or so that Vitalik Butering gave to the Future of Life institute. It sounds like he wanted it spent on research more than advocacy and is now distancing himself from them.

  • j2kun a day ago ago

    FWIW, there has already been a lot of effort thrown at AI attacking lattice problems underlying PQC without anything to show for it. I'm not sure why Vitalik is suddenly worried about lattice problems in particular, unless he has some insider knowledge.

    • dist-epoch a day ago ago

      The AI unit distance conjecture proof used high-dimensional lattices and algebraic number fields, adjacent to the kind of stuff used in lattice PQC. It shows skill in that area.

      • j2kun 20 hours ago ago

        And if the same AI has tried and failed to break lattice problem security, wouldn't that suggest the problems are more secure, not less?

  • what a day ago ago

    Why should we believe that LLMs are going to break ECC?

    • plesiv a day ago ago

      Your probability distribution should be flatter at least.

    • tptacek a day ago ago

      LLMs probably won't break curve cryptography. Cryptography researchers armed with LLMs are a different story.

      • what a day ago ago

        Okay and why should we believe that?

        • tptacek a day ago ago

          It depends a lot on your priors. I think making existing cryptography researchers hyperefficient and much more mathematically capable is likely to generate some disruptive results, but you may disagree.

          • what 20 hours ago ago

            If this were a real possibility, it would be getting a lot more attention. Not just some crypto bros worried about losing magic beans.

      • contingencies a day ago ago

        Don't forget LLMs can now design efficient high speed hardware systems, a traditional slow-down for many attackers which represents a significant barrier to scalable next-gen attacks falling. Unfortunately memory prices are through the roof, but that isn't always significant.

    • nextaccountic a day ago ago

      It's a risk

    • cidd a day ago ago

      You don't

  • spottedmarley a day ago ago

    It may be a plausible concern at some point in the future but, once it's possible, it would manifest as an extremely expensive and time consuming attack against a targeted address, it would require an enormous amount of compute. So, I suppose the first line of defense would be to never keep more funds locked under one key than it would cost an attacker to decrypt it.

    • _ink_ a day ago ago

      Which leaves Bitcoin between a rock and a hard place. The Satoshi funds are probably worth an attack. At the same time they cannot move to post quantum cryptography, because that would also require to move funds.

      • a day ago ago
        [deleted]
      • spottedmarley a day ago ago

        Yeah the Satoshi treasure would be a prime target. Maybe we see those funds get mysteriously split up at some point? But we wouldn't know if they were hacked or protected..

    • tzone a day ago ago

      There are exchanges, custodians, etc that hold insane amounts of BTC or ETH in a single address.

      We are talking billion dollars+ worth in a single address. So if either chainskey security is compromised in a way that it is conceivable to brute force it, there will definitely be plenty of targets.

      • dist-epoch a day ago ago

        Stealing a billion dollar address is kind of worthless. Try cashing it out. Even if you are NK.

      • spottedmarley a day ago ago

        Yes, it would require those exchanges to move their funds around. I'm pretty sure they can manage it.

    • warkdarrior a day ago ago

      Cost of running an attack is super cheap if one buys botted computers (it is/used to be $25/1000 machines).

  • EA-3167 a day ago ago

    It’s always tragic when the new hype train runs over the old one. It pains my soul to imagine those gentle folks with millions in crypto being subjected to the incredibly foreseeable consequences of their limitless greed.

    • lopsotronic a day ago ago

      Isn't it fascinating how multiple successive hype trains have had the same functional command of "Build Me More Teraflops, Human"?

      I sometimes wonder if the AGI wasn't here all along . . .

      We never did find out who "Satoshi Nakamoto" actually was.

      I'm not seriously suggesting that an AGI has been in the wild since circa 2010s, but . . stranger things have happened. All through the aughts, then the teens, GWoT had been funneling an absolutely bananas amount of money into compute. What if, in those years, something horrifying happened, and it's already taken over. That would explain so much weirdness.